CVE-2024-23819

CVSS 3.1 Score 4.8 of 10 (medium)

Details

Published Mar 20, 2024
Updated: Dec 17, 2024
CWE ID 79

Summary

CVE-2024-23819 is a stored cross-site scripting (XSS) vulnerability affecting versions prior to 2.23.4 and 2.24.1 of GeoServer, an open-source Java-based software for managing and sharing geospatial data. An authenticated administrator with workspace-level privileges can exploit this flaw to insert a malicious JavaScript payload into the GeoServer catalog. When other users view the affected MapML HTML Page, the payload executes in their browser, potentially leading to unintended actions or data exposure. The MapML extension and access to the MapML HTML Page are required for the attack, but data security measures may limit the attack surface. Newer versions 2.23.4 and 2.24.1 include a patch to mitigate this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share